AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2021-37181

CRITICAL · CVSS 10 EPSS 1.89%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2021-09-14 · Last synced 2026-08-04

CyberRota Analysis

This is a critical severity vulnerability with a CVSS score of 10.0. It affects Windows. Exploitation may require the attacker to be authenticated.

CVE
CVE-2021-37181
Severity
CRITICAL
CVSS
10
EPSS
1.89%
Windows

Original NVD Description

A vulnerability has been identified in Cerberus DMS V4.0 (All versions), Cerberus DMS V4.1 (All versions), Cerberus DMS V4.2 (All versions), Cerberus DMS V5.0 (All versions < v5.0 QU1), Desigo CC Compact V4.0 (All versions), Desigo CC Compact V4.1 (All versions), Desigo CC Compact V4.2 (All versions), Desigo CC Compact V5.0 (All versions < V5.0 QU1), Desigo CC V4.0 (All versions), Desigo CC V4.1 (All versions), Desigo CC V4.2 (All versions), Desigo CC V5.0 (All versions < V5.0 QU1). The application deserialises untrusted data without sufficient validations, that could result in an arbitrary deserialization. This could allow an unauthenticated attacker to execute code in the affected system. The CCOM communication component used for Windows App / Click-Once and IE Web / XBAP client connectivity are affected by the vulnerability.

Related CVEs

Other vulnerabilities affecting the same vendor(s)